← Builder hub
The Quantus difference, explained

Quantum Shield

Every other major chain was designed before quantum computing was a credible threat — and will have to retrofit post-quantum cryptography someday. Quantus was built for the quantum era from the genesis block: its signatures are ML-DSA, the NIST post-quantum standard (FIPS 204), immune to the algorithm that breaks ECDSA. This page explains why that matters — with every claim sourced and every number checkable.

01 · The threat

Shor's algorithm breaks every classical signature

Bitcoin, Ethereum, and nearly every chain in production secure coins with ECDSA or Ed25519 signatures. Both rest on math problems — the elliptic-curve discrete logarithm — that Shor's algorithm solves in polynomial time on a sufficiently large quantum computer. When such a machine exists, a published public key can be turned into its private key in minutes to hours, versus 2128-class effort for classical computers. Schnorr signatures (Bitcoin Taproot) fall the same way.

✓ No such machine exists yet

NIST notes that no cryptographically relevant quantum computer has been built. Breaking ECDSA-256 needs on the order of ~1,200–1,450 logical qubits (about a million noisy physical ones, per a March 2026 Google Quantum AI estimate) — current chips run ~1,000 noisy physical qubits. The threat is real but not live today.

⚠ But exposure starts before the machine does

“Harvest now, forge later.” Any address whose public key was ever revealed on-chain — a spent address, a Taproot output, P2PK — can be archived today and forged the day the machine arrives. Blockchains are immutable, so that exposure can't be retroactively patched. The U.S. Federal Reserve (2025) flagged this as an ongoing risk for distributed ledgers, not a future one.

How we got here

1994Shor's algorithm published — polynomial-time factoring and discrete logs on a quantum computer.
2016NIST opens the post-quantum cryptography standardization process; CRYSTALS-Dilithium (later ML-DSA) is a candidate.
Aug 2024FIPS 204 published — ML-DSA becomes the U.S. federal standard for post-quantum digital signatures.
Sept 9, 2026Quantus mainnet launches with ML-DSA signatures from block one — no retrofit required, ever.
2027–2030sEstimates for a cryptographically relevant quantum computer: Citi Institute (Jan 2026) says most likely 2027–2030; the U.S. National Academies point to the 2030s. Ranges, not dates — but the trend line is one direction.
02 · The standard

ML-DSA: lattice math instead of elliptic curves

ML-DSA (Module-Lattice-Based Digital Signature Algorithm), standardized as NIST FIPS 204 on August 13, 2024, is built on the hardness of lattice problems (Module Learning With Errors and Module Short Integer Solution) — problems with no known quantum shortcut. It descends from the CRYSTALS-Dilithium submission. NIST defines three parameter sets, trading size against security category:

Parameter setSecurity categoryRoughly equivalent toPublic keySignature
ML-DSA-44Category 2breaking SHA-256/SHA3-256 collisions1,312 B2,420 B
ML-DSA-65Category 3AES-192 key search1,952 B3,309 B
ML-DSA-87 used by QuantusCategory 5AES-256 key search2,592 B4,627 B

Categories are NIST's five post-quantum security levels from the standardization process. Values per FIPS 204; cross-checked against multiple PQC references.

03 · Interactive

Signature-size explorer

Post-quantum signatures are big — that's the honest cost of lattice security. Select a parameter set and compare it against classical signatures. An ECDSA signature is ~65 bytes; one ML-DSA-87 signature is ~4,627 bytes — about 71× larger.

Selected ML-DSA signature
4,627 B
ECDSA (secp256k1)
65 B
Ed25519
64 B
Schnorr (BIP-340)
64 B
Security category
5
≈ AES-256 key search
Public key
2,592 B
vs 33 B compressed ECDSA
ECDSA sigs that fit inside
≈71
4,627 ÷ 65
NIST reference impl.
FIPS 204
qp-rusty-crystals, NIST-ACVP KAT-verified
04 · The scaling answer

Big signatures, aggregated away

A transparent Quantus transaction is ~7 KB — roughly 70× a ~100-byte Bitcoin transaction. If every transaction carried its full signature on-chain, a 12-second, 3.75 MB block would hold about 510 transactions ≈ 43 TPS. Quantus answers this with native transaction aggregation: users generate compact Plonky2 ZK proofs, and batches of proofs collapse into one succinct proof posted on-chain — packing about 5,200 transactions per block ≈ 430 TPS. Try it:

Transparent mode ~510 tx/block
10 blocks · ~2.0 min
Aggregated mode ~5,200 tx/block
1 block · ~12 s

Packing figures from Quantus's architecture docs (design figures from testing: ~43 QTPS transparent, ~430 QTPS encrypted two-layer aggregation), 12-second blocks. Not measured mainnet throughput — watch the Network Dashboard for live numbers.

05 · Interactive

Are your coins quantum-exposed?

Click each address archetype to see its quantum story. The rule is simple: once a public key is on-chain, it can be harvested today and forged tomorrow — blockchains can't un-publish history.

06 · Under the hood

What Quantus actually runs

From the Quantus architecture docs and upstream repos (checked Sept 29, 2026):

Audited by Neodyme, Eiger, Hashcloak, and V12 with an Immunefi competition, per September 2026 launch coverage. First exchange venue announced: NEAR Intents (no listing date confirmed as of Sept 2026).

07 · FAQ

Straight answers

Is Bitcoin broken right now?

No. No cryptographically relevant quantum computer exists, so ECDSA and Ed25519 are safe today. The risk is forward-looking: public keys already exposed on-chain are archivable now and attackable later. Coins in never-spent hashed addresses stay safe until their key is revealed by spending.

Why not just upgrade old chains later?

Upgrading signatures is the easy part; the hard part is the history. Every exposed public key ever published stays exposed forever. A chain that retrofits PQC in 2030 still has 20+ years of harvestable keys. Starting with ML-DSA at genesis means there is no pre-quantum history to exploit — that window never opened.

Does ML-DSA-65 vs 87 matter?

Both are NIST-standardized; Category 5 (ML-DSA-87) targets AES-256-equivalent effort versus AES-192 for Category 3 (ML-DSA-65). Quantus runs ML-DSA-87 on-chain per its architecture docs — the strongest setting — while the quantus-cli wallet tool defaults to ML-DSA-65 with 87 available.

Are there downsides to post-quantum signatures?

Honestly, yes: size (a 4.6 KB signature vs 65 bytes) and somewhat slower verification. Quantus's answer is native aggregation — the per-transaction on-chain footprint shrinks as batches grow. The tradeoff is deliberate: pay bytes now, never face a migration cliff later.

Could quantum computers break ML-DSA too?

No known quantum algorithm breaks the lattice problems ML-DSA rests on — that's the entire basis of the NIST standard. Cryptography is never "proven" safe, but ML-DSA survived the most scrutinized selection process in the field's history and is the U.S. federal standard.

Where do I read the real specs?

Start with FIPS 204 itself, Quantus's architecture docs, the qp-rusty-crystals implementation, and the quantus-cli README.

08 · Receipts

Sources

Every figure on this page was re-verified against these sources on Sept 29, 2026. If a source moves, the claim moves with it — nothing here is asserted on vibes.